Skip to navigation
Latest News

DIY phishing kits widely available on the Net

By Alun Williams

Posted on 19 Aug 2004 at 11:33

DIY phishing kits are being widely made available on the Internet warns the security company Sophos.

'Phishing' is the practice of duping people to reveal sensitive financial information by means of bogus websites and emails, often purporting to come from trusted sources. This development can only increase the incidence of attacks. Indeed, these are already starting to rival spam in terms of the numbers of emails involved - Phishing scams rival virus attacks in email tally

'Until now, phishing attacks have been largely the work of organised criminal gangs,' warned Graham Cluley, senior technology consultant at Sophos. 'The emergence of these "build your own phish" kits, however, mean that any old Tom, Dick or Harry can now mimic bona fide banking websites and convince customers to disclose sensitive information such as passwords, PIN numbers and account details.'

According to Sophos, the DIY kits contain graphics, source code and example text to help construct bogus websites that have the look-and-feel of legitimate online banking sites. Inevitably, there is also a link with spamming - software is included that enables potential fraudsters to pump out phishing emails as bait.

The motive, of course, is financial and eastern European gangs are already specialising in such attacks. Others are likely to try and follow in such fraudulent footsteps. 'There is plenty of profit to be made from Phishing,' said Cluley. 'By putting the necessary tools in the hands of amateurs, it's likely that the number of attacks will continue to rise.'

Certainly the current prevalence of phishing should not be underestimated. Such scams are already estimated to cost banks and other financial institutions as much as $400mn in fraud this year, according to research group Financial Insights. And reported incidences of phishing scams are running at more than a thousand a month, according to the Anti-Phishing Working Group. Such a situation can only worsen if Phishing-kiddies start getting in on the act, too.

You can see examples of phishing scams in this earlier article.

See also:

Cost of Phishing scams estimated at $400mn this year

Phishing scams rival virus attacks in email tally

Phishing scams rise 50 per cent in a month

Phishing: Real scams, fake sites

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.